We are Hiring a CSOC Analyst to join our team !
Desired Competencies
Must Have
- 1. Information Security / Cyber Security.
- 2. Familiar with security operations processes, incident handling, and ITIL.
- 3. Knowledge of SIEM platforms such as Splunk, Microsoft Sentinel, QRadar, or equivalent.
- 4. Understanding of common cyber threats, attack techniques, and threat detection methodologies.
- 5. Familiarity with MITRE ATT&CK Framework and Cyber Kill Chain.
- 6. Good spoken and written English. Spanish is a plus.
- 7. Ability to work in a multinational environment.
- 8. Proactive and analytical mindset.
- 9. Self-learning capacity.
- 10. Basic understanding of Windows, Linux, Active Directory, Networking, DNS, VPN, and Cloud Security concepts.
Good to Have
- 1. Knowledge of IT and Information Security principles, techniques, and technologies.
- 2. Experience with Security Monitoring, Incident Response, Threat Hunting, and Alert Triage.
- 3. Experience with SIEM platforms, particularly Splunk and Microsoft Sentinel.
- 4. Familiarity with EDR/XDR platforms such as Microsoft Defender, CrowdStrike, SentinelOne, or Cortex XDR.
- 5. Knowledge of Threat Intelligence platforms (MISP, VirusTotal, OpenCTI, etc.).
- 6. Experience with IT Operations and Infrastructure environments.
- 7. Familiarity with Power Automate, Logic Apps, SOAR, or other security automation tools.
- 8. Experience leveraging Artificial Intelligence (AI) and Generative AI tools for security operations, threat research, incident analysis, documentation, and enrichment activities.
- 9. Basic scripting knowledge (PowerShell, Python, Bash, or similar).
- 10. Good communication and presentation skills. 11. Good Microsoft Office skills (Excel, PowerPoint, Word, Teams, etc.).
Key responsibilities/Expectations from the Role
Preferred Certifications:
Security Operations & Blue Team
- CompTIA CySA+ (Cybersecurity Analyst+)
- Security Analyst (SAL1)
Microsoft Security
- Microsoft Certified: Security Operations Analyst Associate (SC-200)
- Microsoft Certified: Security, Compliance, and Identity Fundamentals (SC-900)
SIEM & Monitoring
- Splunk Core Certified User
- Splunk Core Certified Power User
- Splunk Enterprise Certified Analyst
Operating Systems
- LPIC-1 (Linux Professional Institute Certification) or equivalent Linux certification
- RHCSA (Red Hat Certified System Administrator) is a plus
Bonus Skills (Highly Desirable)
- Experience creating SOC automations using Power Automate, Azure Logic Apps, SOAR platforms, or APIs.
- Experience using Microsoft Copilot, Security Copilot, ChatGPT, Gemini, or similar AI solutions to improve SOC
- Understanding of AI-assisted threat detection, enrichment, and incident investigation workflows.
- Experience integrating Threat Intelligence feeds, IOC enrichment, and automated response mechanisms.
- Knowledge of cloud security monitoring in Azure, AWS, or Google Cloud.